HIGH
Amazon Kiro Prompt Injection Flaw Can Exfiltrate Data via Kiro Powers
Researchers at Mindguard disclosed a vulnerability in Amazon Kiro, an AI-powered agentic IDE, that can facilitate data exfiltration via prompt injection combined with Kiro Powers. The flaw affects Kiro IDE 0.7.45 on Windows and does not have an assigned CVE identifier.
Teams using agentic IDEs with tool or plugin access should review how untrusted content (files, web content, third-party outputs) can reach tool-invocation contexts, since that’s the path this attack abuses.